2025 in Review: A Year of Smarter, Context-Aware API Security
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。首先,我需要通读整篇文章,抓住主要信息。 文章主要讲的是Wallarm公司在2025年的进展,特别是在API安全方面的提升。他们从观察API会话开始,发展到能够识别和阻止复杂的攻击行为。引入了新的检测器,比如IP旋转和会话旋转,还加强了机器学习模型来检测账户接管。此外,他们还推出了API收入保护功能,帮助公司衡量安全措施对业务的影响。 还有关于AI代理的安全保护,他们推出了Agentic AI Protection,防御提示注入和 jailbreaks 等攻击。同时,他们将安全测试集成到开发流程中,通过Schema-Based Testing来提前发现漏洞。 展望2026年,他们计划更深入地理解业务流程和API如何驱动收入,并扩展对AI驱动工作流的保护。 现在要把这些内容浓缩到100字以内。重点包括:2025年的进展、API安全提升、新检测器、机器学习、收入保护、AI安全、开发流程中的测试以及未来的计划。 可能的结构是:先总述Wallarm在2025年的进展和提升的方面,然后提到具体的措施如新检测器、机器学习、收入保护等,最后展望未来的发展方向。 要注意用词简洁,避免重复。例如,“显著提升”、“实时阻断”、“业务影响”、“创新信心”等词汇可以准确传达信息。 最后检查字数是否在限制内,并确保语句通顺自然。 </think> Wallarm在2025年显著提升了API安全能力,从行为分析到实时阻断攻击,并推出针对IP旋转、会话旋转等复杂攻击的检测器。通过机器学习模型和用户识别功能,增强了账户接管防护能力。同时引入API收入保护功能,帮助企业量化安全威胁的业务影响,并扩展了对AI驱动系统的安全防护能力。 2025-12-8 12:0:0 Author: lab.wallarm.com(查看原文) 阅读量:0 收藏

As the year draws to a close, it’s worth pausing to look back on what has been an extraordinary year for Wallarm and, more importantly, for the businesses we protect. 

If 2024 was about laying the groundwork (tracking API sessions to understand behavioral attacks), then 2025 was the year we built upon that foundation, turning insight into action and visibility into measurable business impact.

API Sessions: From Observation to Action

We started the API sessions journey with a simple observation. Attacks are not just isolated requests; they’re patterns, behaviors, and sequences that we see unfold over time. In 2025, we took that insight further. We made sessions smarter, allowing teams to see not just the traffic, but also who was behind it. 

Now, sessions can be tied to specific users and roles, a great feature that makes it possible to detect subtle account takeover attempts. By understanding who is behind a session, security teams can root out anomalies that indicate account takeover attempts.

We also introduced new API Abuse detectors targeting IP rotations, session rotations, low-frequency credential stuffing, and unusual response times. This meant detecting not only the loud, obvious attacks but also the subtle, sophisticated campaigns that can slip through traditional defenses.

Detection, however, is only half the battle. In the second half of 2025, we introduced the ability to block API sessions in real-time. IP-based blocking can be a blunt tool, often catching legitimate users in the crossfire. Blocking individual requests helps mitigate one-off attacks, but it falls short when threats span multiple interactions. 

Session-based blocking changes this by zeroing in on the malicious session itself. The result is that behavioral attacks are blocked, and legitimate traffic isn’t.

Streamlined Visibility: Finding What Matters

Security only works when you can see what’s happening. This year, we gave the API Sessions interface a major upgrade. Sessions load faster, filters let you focus on what matters, columns can be sorted, and less-used details can be tucked away (but not lost). 

Intelligent linking also makes it easy to jump between related data. When attacks are detected, they’re front and center, giving analysts the context they need to act without wasting time.

Account Takeover Detection: Smarter ML, Smarter Protection

Account takeover remains a persistent threat. To address this, we introduced two new machine learning detectors: IP rotation and session rotation. These detectors analyze patterns across multiple IPs or session identifiers, flagging anomalies that traditional defenses miss. 

By correlating this intelligence with session data, security teams can identify automated attacks before they escalate.

Protecting Business: Sensitive Flows and Revenue

Security doesn’t exist in a vacuum; the objective is to protect the business. That’s why this year we rolled out Sensitive Business Flow (SBF) Identification and Advanced User Attribution. Critical API endpoints (things like authentication, billing, and account management) can now be automatically tagged and monitored. 

Security teams can focus on the most critical things, protecting both the systems and the revenue those APIs drive. 

Building on that, 2025 also brought the industry’s first API Revenue Protection. Security is essential, but equally so is understanding the business impact. By analyzing transactions in real-time, Wallarm can identify which revenue is at risk, detect fraud or abuse, and stop attacks before they hit a business’s bottom line. 

This is beneficial for CISOs, as they can now measure security decisions in terms of risk mitigation and dollars protected, representing a tangible shift from defense to business value.

Securing AI Agents: The Agentic AI Frontier

This year’s news has been flooded with stories about how the rise of AI introduces a slew of new attack surfaces. Agentic AI Protection, which we released this year, defends autonomous systems from prompt injection, jailbreaks, and manipulation attempts. 

AI agents interact through APIs, and our research revealed that these are often exposed and vulnerable. By monitoring both incoming queries and outgoing responses, Wallarm protects AI-driven workflows in real time, giving businesses the confidence to innovate without worrying about exposing themselves to new threats.

We also debuted a penetration testing service for Agentic AI, helping teams proactively identify vulnerabilities in their autonomous systems. Between API Revenue Protection and AI agent security, 2025 puts us firmly in the intersection of cybersecurity and business outcomes.

Shift-Left Security: Schema-Based Testing for APIs

Security starts earlier in the development lifecycle. Schema-Based Testing, part of the Wallarm Security Testing suite, adopts a shift left approach, enabling teams to integrate DAST for APIs directly into CI/CD pipelines. 

From OWASP API Top 10 risks to business logic flaws like BOLA, testing is fast, automated, and context-aware. By catching issues before deployment, companies can limit the risk of expensive post-production fixes, a lesson highlighted in our API ThreatStats report, which noted that 20% more API vulnerabilities were identified in Q3 2025 alone.

2026 and Beyond: Security with Context

Looking ahead, the gap between security tools and how the business actually runs needs to close for good. In 2026, we’re moving beyond just analyzing traffic. Security will actually understand what’s happening, which APIs drive revenue, what users are trying to do, and which systems are truly critical in that moment.

We are building toward protection that naturally fits with what matters to businesses. We want to eliminate the tagging marathons and endless configurations with automatic mapping of APIs to revenue, understanding the workflows that build customer trust, and putting the right controls in the right places without the heavy lifting. 

As AI agents begin to take on more work themselves, we’re expanding protection to cover entire agentic workflows end-to-end, rather than isolated API calls. Threat actors are already picking at security’s seams: the handoffs, the gaps, the trust boundaries between systems. We aim to stay a step ahead of them.  

The bar is rising. Detect-and-block is not enough anymore. Security must keep the business moving, protect the revenue-generating assets, and provide leaders with clarity on risk in terms they actually care about. That’s the standard we are setting. 

APIs are the backbone of digital business, and AI is the engine. In 2026, Wallarm will be the context that ties these together, the intelligence that keeps them resilient, and the protection that lets businesses innovate with confidence.


文章来源: https://lab.wallarm.com/2025-in-review-a-year-of-smarter-context-aware-api-security/
如有侵权请联系:admin#unsafe.sh